Privacy
What we hold, what we don't, and why.
Last updated August 2026
Draft, pending legal review. This document is being finalised with a Greek healthcare and data-protection lawyer before the clinic opens. It describes our actual intended practice, but it is not yet the signed-off version — treat it as a statement of how we mean to work.
Who we are
The High Clinic operates this platform and is the data controller for the personal data described here. You can reach our privacy contact at privacy@thehighclinic.com. The doctors who treat you are independent practitioners and act as controllers in their own right for the clinical decisions they make.
The three kinds of data we hold
We deliberately keep three categories of information apart, and treat each one differently.
Your consultation. Everything you tell a doctor during an intake session. Stored encrypted, shown only to you and the doctor treating you, and never used for our own analysis or reporting. Held on the basis of performing our contract with you and, for health data, your explicit consent.
Who you broadly are. Age, gender, language, region. Used in aggregate to understand whether the clinic is working — how many people we saw, how many were helped, where the process fails. Held on the basis of our legitimate interest in running a functioning service.
Your ΑΜΚΑ or passport number. Used solely to have a prescription issued in the national system, and held for the minimum period required. Your ΑΜΚΑ is optional on your profile.
What we do not do
We do not use the content of your consultation for analytics, product development, marketing, or training any model. We do not sell personal data. We do not share your identity with anyone outside the clinic and the doctor treating you.
Where we are required to report on prescriptions, those reports contain prescription-level facts only — product, quantity, date, prescription number, prescribing doctor — and nothing that identifies a patient.
Who processes data for us
We use a small number of providers to run the service: hosting, authentication, payment processing, email delivery, and the AI service that runs the intake conversation. Each is bound by a data processing agreement, each is used for one defined purpose, and none is permitted to use your data for its own ends. A current list is available on request.
How long we keep things
Medical records are kept for the period Greek law requires of medical records. Identity data used for prescribing is kept for the minimum period required and then removed. Demographic aggregates are kept indefinitely in a form that cannot be traced back to you. Account data is deleted when you close your account, subject to those legal retention duties.
Your rights
You can ask for a copy of what we hold, ask us to correct it, ask us to delete it, object to a particular use, withdraw consent, or ask for it in a portable form. Write to privacy@thehighclinic.com and we will respond within one month. If you are unhappy with how we handled it, you can complain to the Hellenic Data Protection Authority.
Security
Consultation content is encrypted at rest and in transit. Access is restricted to the patient and the treating doctor; nobody in the business can read it in the course of ordinary work. We log administrative access and review it.